Plain-English
privacy.
What we collect, why we collect it, and how to delete everything. Written so a person can read it, not just a lawyer.
tl;dr
Your speech is transcribed on your iPhone with Apple's Speech framework. The audio is processed in memory and discarded — no recording is saved, no audio is uploaded. To turn your words into a map, the backend receives the transcribed text only, sends it to an AI provider (Google Gemini) to extract structure, and stores only the resulting map. There is no transcript artifact. No ads, no resale, no third-party trackers in the app, and nothing is used to train AI models.
Who we are
Overscope is operated by Alican Basak, based in Istanbul. Contact: hello@overscope.app. We are the data controller for everything described below.
What we collect
Your account
When you sign in with Apple, we receive an opaque Apple user ID and (if you allowed it) a private relay email address. We do not see your real name or your real email. We store the Apple user ID, the relay email (if provided), the date you joined, and your subscription state.
Your speech and audio
Speech is transcribed on your device using Apple's Speech framework with on-device recognition. The audio buffer is processed in memory and discarded immediately — no audio file is ever saved or uploaded. We never receive your voice.
Your maps
A map is the structured output of a capture: a title, the nodes (short concept labels — not your sentences), the language, and timestamps. This is the core of the product. Stored in our database until you delete the map or your account.
Turning text into structure
To build the map, the transcribed text is sent once to the backend, which forwards it to an AI provider to extract the structure. We store only the returned map. We do not store the raw transcript, and there is no transcript view or export anywhere in the product.
Subscription state
If you subscribe, we receive billing state from Apple via RevenueCat: which plan, when it started, when it renews, whether it's active. We do not see your card number, billing address, or Apple ID email. Apple handles payment; we handle access.
Aggregate analytics
We track product events: app opened, a map created, a paywall shown, an upgrade completed. We also log session metadata — a timestamp, a capture's duration, a map's node count. We never send your speech, the transcribed text, node labels, or any map content. Events are pseudonymous (a random user ID, not your Apple ID).
What we do not collect
- We do not save or upload any audio — ever.
- We do not keep a transcript of what you said.
- We do not see your real name or email unless you write to us.
- We do not access your contacts, calendar, photos, or any file on your device.
- We do not track you across other apps or websites, and we have no advertising partners.
- We do not sell, rent, or share your data for marketing.
- We do not use your speech, text, or maps to train any AI model — neither ours nor a third party's.
How AI features work
Transcription runs entirely on your device. To extract structure, the backend sends the transcribed text to an AI provider (Google Gemini by default) over its commercial API. The provider is contractually obligated not to retain your inputs after processing and not to train on them. We do not opt into any training programs. After the model responds, we store only the returned map.
Sub-processors
We use the following companies to run Overscope. Each is contractually bound to handle your data only as we direct.
- Apple — Sign in with Apple, App Store, push notifications. Receives Apple user ID and subscription receipts.
- Railway — API hosting and the Postgres database. Receives your maps and account record.
- Google — AI processing (Gemini API) to extract map structure from transcribed text. Text for AI calls only; not retained, not used for training.
- RevenueCat — Subscription state. Apple user ID and subscription status.
- PostHog — Pseudonymous product analytics (EU instance). Event names and session metadata only — never your speech, text, or map content.
- Vercel —
overscope.applanding site and legal pages. Public content only.
We will update this list before adding a new sub-processor.
Where your data lives
Our Postgres database lives in our Railway project. AI processing (Google) happens under standard contractual clauses (SCCs) for GDPR, with retention not permitted at the processor.
Deleting your data
In the app: Settings → Account → Delete Account. We erase everything within 30 days. We can also do it manually if you email hello@overscope.app.
Your rights (GDPR, KVKK, CCPA, LGPD)
You have the right to access, correct, export, and delete your data. Reach out at hello@overscope.app and we'll handle it within 30 days.
Children
Overscope is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have, please email us and we will delete the account.
Changes to this policy
We post material changes here. The effective date at the top moves; the substance always matches.
Contact
For privacy questions: hello@overscope.app.